Privacy Policy
FireSat, bsv20.com and the FireSat API
Effective date: 2 December 2026
Version 1.0
The short version
- FireSat is a non-custodial wallet. Your recovery phrase and private keys
are created and stored on your device. We never receive them, and we cannot
recover them for you.
- No name, email or phone number is needed. We know you only by the
wallet addresses you use.
- Blockchain data is public. Anything recorded on the BSV blockchain can
be seen by anyone, permanently. Our explorer and app display it.
- Social features are optional. If you create a public profile, post in
chat, follow wallets or react, other people can see it.
- We do not sell your personal data, and we do not use it for advertising.
- You are in control. You can edit or hide your profile, turn
notifications off, and delete your account data from the app at any time.
The rest of this policy explains the details.
1. Who we are
The Services are operated by CipherVybe (OPC) Private Limited, a company
incorporated in India:
- CIN: U62010AS2025OPC027949;
- registered office: H.No. 224, F/No. 3B, Rajgarh, Bylane 10, Silpukhuri, Guwahati, Kamrup, Assam 781003, India.
In this policy, "CipherVybe", "we", "us" and "our" mean that
company.
This policy covers the following, together called the "Services":
- the FireSat app: the FireSat mobile apps for Android and iOS, and the
FireSat web app at app.firesat.io;
- the websites: firesat.io, and bsv20.com, including the bsv20.com
BSV-20 token explorer and the FireSat Pro purchase page;
- the FireSat API at api.firesat.io, also called the BSVScan API. It
powers the app and the websites, and developers can use it directly.
For the personal data described here, we are the Data Fiduciary under
India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). For
people in the European Economic Area or the United Kingdom, we are the
controller under the GDPR.
Please read this policy together with our Terms of Service.
2. Wallet addresses are personal data
A BSV wallet address does not contain your name. However, an address can be
linked to a person, for example when you share it or when it appears beside
your username. We therefore treat your wallet addresses, and everything we
hold about them, as personal data and protect them under this policy.
3. What we do not collect
- Recovery phrase and private keys. These are generated on your device
and stay there. The app uses them on your device to sign transactions and
sign-in messages. Only the resulting signatures leave your device; the keys
themselves are never sent to us or anyone else.
- Identity details. We do not ask for your name, email address, phone
number, date of birth or government ID. We do not perform KYC. If you email
us, we receive your email address and whatever you choose to write (see
section 4.11).
- Device access. We do not access your precise location, contacts,
microphone or photo library. The only exceptions are a photo you choose
to upload as your profile picture, and a Shill or P&L card you choose to
save, which the app adds to your photos without reading them.
- IP addresses in our databases. Your IP address appears only in
short-lived server logs and in temporary rate-limit counters (see section
4.9).
4. What we collect and why
4.1 Public blockchain data
What:
- addresses;
- balances and token holdings;
- token deployments and mints;
- marketplace listings, purchases and transfers;
- the times and blocks at which these happened.
We collect this for every address on the BSV blockchain, not only yours.
We also calculate figures from it, such as cost basis, profit and loss, and
trading volume.
Where it comes from: we read it from the public BSV blockchain through our
own node.
Why:
- to show your wallet and the token market;
- to run the bsv20.com explorer, activity feeds, leaderboards and charts;
- to check transactions before they are broadcast.
4.2 Sign-in data
Some features need proof that you control a wallet, such as editing a profile,
chat, follows, alerts and notifications. For these, the app asks your wallet
to sign a short message on your device. The message begins "BSVScan sign-in"
and ends "No transactions authorized." Signing it cannot move your funds.
What we store:
- the sign-in request: your address, the message and its expiry time;
- your session: a one-way hash of the session token, your address and the
expiry time;
- a sign-in record: when you first and last signed in, and how many times.
Why:
- to confirm that requests really come from the wallet's owner;
- to keep your session secure;
- to prevent abuse of invites, which require a recent sign-in.
4.3 Your profile (optional)
A profile is optional. If you create one, we store:
- your username, display name and bio;
- your website and your X and Telegram handles;
- your profile picture;
- your visibility setting (public or private);
- creation and update times, and the time of your last username change.
Profile pictures are re-encoded when uploaded, which removes hidden metadata
such as camera details and location.
Why: to show your identity in the app, on bsv20.com and on share pages.
4.4 Social activity (optional)
What:
- Follows: the wallets you follow, and whether you want notifications
about each one.
- Reactions you add to trades, mints and messages.
- Chat messages you post in token chats. This includes replies, and the
wallets you mention. Once posted, a message can't be edited or deleted on
its own; deleting your account data removes all of them.
- Blocks: the wallets you block.
- Reports you file: the reason and any note you add.
- Invites: your invite code, who joined through it, and who invited you.
- Badges on your profile, whether granted by us, bought (Pro) or earned
automatically from on-chain activity.
Why:
- to provide social features, feeds, notifications and leaderboards;
- to keep the community safe;
- to prevent spam and abuse.
4.5 Watchlists, alerts and notifications
What:
- tokens on your watchlist;
- price, liquidity and listing alerts you create;
- your notification settings, and the notifications we send you;
- push tokens: the identifier Google Firebase Cloud Messaging assigns to
your device for push notifications, linked to the wallet addresses for
which you turn notifications on.
The app creates a push token only when you turn notifications on, and
deletes it when you turn them off. If you allowed notifications in an
earlier version of the app, they stay on after you update.
If you turn on notifications for several wallets on the same device, those
wallets share a push token, so we can see that they are used on the same
device.
Why: to send the alerts and notifications you ask for, and to let you
manage them.
4.6 Transactions you send through us
When you send a transaction from the app, we check it before it is
broadcast. We then relay it to the BSV network, or the app broadcasts it
through a blockchain data provider.
What we record for each transaction:
- its transaction ID and size, and the type of operation;
- which earlier outputs it spends;
- the time, the result, and any error the network returned;
- a short abuse-detection code. This is a one-way code made from your
IP address and a secret key. The key is replaced whenever our server
restarts. The code lets us spot floods of requests from one source, but it
cannot be turned back into your IP address.
The raw transaction itself is not stored in this record.
Transactions created by earlier versions of the app carried a small public
marker identifying them as FireSat transactions; like the rest of a
transaction, it is visible on the blockchain. The current app adds no
marker.
Why:
- to show the status of your transaction;
- to stop invalid or duplicate transactions;
- to protect the Services from abuse.
4.7 FireSat Pro purchases
What:
- the address of the profile receiving Pro;
- the payment address we generated for the purchase;
- the price, the amount received and the paying transaction ID;
- the purchase and expiry times;
- the purchase status.
We do not know who paid, except for what the public blockchain shows.
Why:
- to detect your payment and grant the Pro badge;
- to handle failed or reversed payments;
- to keep the payment records that accounting and tax law require.
What: the display name, description, links and icon you submit for a
token (website, X, Telegram, Discord), and your wallet address as the
submitter.
Why: to show token information. The submitter's address is shown publicly
so that others can see where the information came from.
4.9 Technical and log data
Server logs. Our web servers record standard request logs:
- your IP address and the date and time;
- the address (URL) requested, which may contain a wallet address or
transaction ID;
- the response status;
- the referring page;
- your browser or app identifier (user agent).
Rate limits. Our API counts requests per IP address in memory only to
apply rate limits. A counter is discarded after 10 minutes without requests.
API logs. Our API's own logs record which kind of request failed or was
slow. They do not record IP addresses, user agents, sign-in tokens or request
contents.
Why:
- to keep the Services secure and available;
- to prevent abuse;
- to fix problems;
- to meet legal requirements on keeping logs.
4.10 Analytics and crash reports (only with your permission)
The app asks whether you want to share analytics and crash reports. If you
agree, we use Google Firebase Analytics and Firebase Crashlytics to
collect:
- your device model, operating system and app version;
- your language;
- a random app-instance identifier;
- an approximate location (country or city) derived from your IP address;
- the screens and features you use;
- crash details.
We do not use your device's advertising identifier, and we do not use this
data for advertising. You can change your choice at any time in the app's
settings.
Why: to find bugs, understand which features are used, and improve the
app.
4.11 Support requests
If you email us, we receive your email address, your message and anything you
attach.
Why: to answer you, and to keep a record of your request and our reply.
4.12 Developer API keys
The public API needs no key. If we issue you a key for higher limits, we
record:
- the name and contact details you give us;
- the key's tier;
- daily request counts.
The key itself is stored only as a hash.
Why: to apply rate limits, contact you about your key, and prevent abuse.
4.13 Data kept only on your device
The app keeps some data on your device. It is not sent to us:
- your recovery phrase and private keys;
- wallet names;
- which versions of the Terms and this policy you accepted, and when;
- a copy of your notifications;
- your settings;
- cached prices;
- the transactions you sent that haven't settled yet (their IDs and the
earlier outputs they spend), so the app doesn't spend the same outputs
twice. Each entry is removed when its transaction confirms or fails, and
after 48 hours at the latest;
- an invite code from a link you opened, until a wallet claims it. A link
someone shared (a token, a profile or a trade) can carry their invite
code too; on Android, after you install the app from such a link, the
app reads the code from Google Play's install referrer once. A code from
a shared link is kept only while there is no wallet on the phone.
Claiming sends the code to us to record who invited you (section 4.4); a
code that can't be claimed is deleted.
Where it is stored:
- On Android and iOS, the app uses the operating system's secure storage:
Android's encrypted storage protected by the Android Keystore, and the iOS
Keychain.
- In the web app, wallet data is kept in your browser's storage on your
computer. Anyone with access to your browser profile, or a malicious browser
extension, may be able to read it. We recommend the mobile apps for
significant amounts.
Removing a wallet, or deleting the app, erases this data from the device. You
can only restore a wallet with its recovery phrase.
5. What is public
The Services are partly a public explorer and a social platform. The following
is visible to anyone, including people who do not use FireSat. Search engines
and other services may also collect it.
- Blockchain data for any address: balances, holdings, listings, trades,
activity in feeds, and figures calculated from them. This includes cost
basis and profit and loss.
- If your profile is public:
- your profile fields;
- your badges;
- your follower and following counts;
- the list of wallets you follow;
- your join date.
- Trading results for any address: profit and loss and portfolio value,
calculated from blockchain data, on wallet and profile pages, leaderboards
and share cards.
- Chat messages, together with the wallet address that posted them. This
applies even if you have no profile.
- Follower counts for any address.
- Reactions from people with public profiles.
- Leaderboards, which rank wallets by trading activity and results. A
wallet without a public profile is shown by a shortened address.
- Share pages and their preview images for profiles, trades and invites.
These are public web pages. Anyone can create a trade share page for any
verified purchase. Buyers and sellers are shown by username if they have a
public profile, and otherwise by a shortened wallet address.
- Token information you submit, with your wallet address as the submitter.
What the privacy settings do:
- Making your profile private hides it from others. Your username stays
reserved for you, so it will show as taken.
- There is no setting to hide trading results. They are calculated from
trades that are public on the blockchain, which our explorer, and anyone
else's, can do for any address.
6. How we use personal data
We use personal data only for these purposes:
- To provide the Services you request. This includes:
- your wallet view, the marketplace and the explorer;
- sign-in;
- social features and notifications;
- FireSat Pro.
- To keep the Services secure: preventing fraud, spam and abuse, and enforcing
our Terms of Service.
- To moderate content and handle reports.
- To answer your requests and support questions.
- With your permission, to understand how the app is used and to fix crashes.
- To meet legal obligations: accounting and tax records, and responses to
lawful requests from authorities.
What we never do with it:
- We do not sell personal data.
- We do not show advertising.
- We do not build advertising profiles.
Automated decisions. We do not make automated decisions that have legal
or similarly significant effects on you. Some things are automatic:
- badges based on on-chain activity, such as "token deployer" or a number of
trades;
- rate limits.
Our team can review either of these.
7. Legal grounds
In India, we process personal data:
- with your consent, which you give when you start using the app or a
feature and agree to this policy, and which you can withdraw at any time;
- for legitimate uses permitted by the DPDP Act, for example:
- when you voluntarily provide data for a specific purpose, such as
submitting token information;
- when processing is needed to comply with law or a court order.
Withdrawing consent does not affect processing that happened before. However,
it may mean we can no longer provide the features that depend on it.
In the EEA and the UK, we rely on:
| Legal basis |
What it covers |
| Performance of a contract |
Providing the Services you use (sections 4.1 to 4.8) |
| Legitimate interests |
Security, preventing abuse, moderation, and server logs (sections 4.6 and 4.9) |
| Consent |
Analytics, crash reports and push notifications (sections 4.5 and 4.10) |
| Legal obligation |
Accounting records (section 4.7), and responding to authorities |
8. Who we share data with
Everyone. Information described in section 5 is public by design.
The BSV network. Transactions you broadcast go to BSV nodes and miners and
become a permanent, public part of the blockchain. Nobody can delete them,
including us.
Service providers. These process data on our behalf, or because the app
contacts them directly to provide a feature:
| Provider |
Purpose |
What they receive |
| Google (Firebase Cloud Messaging) |
Delivering push notifications |
Your push token and the notification's content. A notification may include the username or address of the person who acted and token details. For mentions and replies, it can include up to 140 characters of the message. |
| Google (Firebase Analytics, Crashlytics) |
Analytics and crash reports, only with your permission |
The data described in section 4.10 |
| Google (Firebase Hosting, Google Fonts) |
Hosting the bsv20.com website and its fonts |
Your IP address and the pages you request |
| Blockchain data providers, such as WhatsOnChain and Bitails |
Balances, spendable coins, exchange rates and broadcasting, requested by the app |
Your wallet address, your IP address, and transactions you broadcast |
| Apple App Store and Google Play |
App downloads and update checks |
The app ID, your country and language, and your IP address |
| Websites hosting token images |
Displaying token icons that token teams provide |
Your IP address, when the image loads |
Others, in limited cases:
- Authorities and legal process. We disclose data when required by law, a
court order or a lawful request from a government agency. This includes
requests under India's Information Technology Act, 2000. We also disclose
data when needed to protect the safety of people or the Services.
- Business transfers. If CipherVybe is involved in a merger, acquisition
or sale of assets, personal data may be transferred to the new owner, who
will remain bound by this policy.
9. Where your data is processed
Our servers are located in India, and your data is processed there. Some
service providers, such as Google, may process data in other countries,
including the United States. We transfer personal data outside India only in
line with the DPDP Act, including any restrictions the Government of India
notifies.
For people in the EEA and the UK, India does not have an adequacy decision.
Where the GDPR applies, we transfer your data because it is necessary to
provide the Services you request, or under other safeguards permitted by law.
10. How long we keep data
| Data |
How long |
| Sign-in requests |
5 minutes |
| Sign-in sessions |
1 hour, then deleted |
| Sign-in record (first and last sign-in) |
Until you delete your account data |
| Profile, follows, reactions, blocks, invites, watchlist, alerts, notification settings |
Until you delete them or your account data, or until we remove them for breaking our Terms |
| Chat messages |
Until you delete your account data, or until we remove them for breaking our Terms |
| Notifications in your inbox |
30 days |
| Push tokens |
Until you turn notifications off for that device or delete your account data. We may delete tokens that stop working. |
| Reports you file |
Until you delete your account data |
| Reports others file about you, and content hidden by moderators |
For as long as needed for safety, investigations and legal claims |
| Records of transactions you send through us |
For as long as needed to show transaction status and protect the Services. These records do not contain your IP address. |
| FireSat Pro payment records |
As long as accounting and tax law requires, generally 8 years. This applies even if you delete your account data. |
| Token information you submit |
Kept as a public record of where the information came from. You can withdraw a submission that is not yet approved. |
| Server request logs |
Up to 180 days, as required by Indian cybersecurity rules |
| Support emails |
As long as needed to resolve your request and keep a record of our reply |
| Backups |
Deleted data disappears from our backups within 7 days |
| Public blockchain data |
Permanent. We do not control the blockchain. |
11. Security
How we protect your data:
- Connections are encrypted with HTTPS.
- Your keys never leave your device.
- Session tokens are stored only as hashes.
- Access to databases and backups is restricted to the people and systems
that need it.
- Our software is regularly reviewed and tested.
No system is perfectly secure. You are responsible for:
- keeping your recovery phrase safe and offline;
- securing your device with a screen lock;
- never sharing your recovery phrase or private keys with anyone.
We will never ask for them. Anyone who does is attempting a scam.
If a personal data breach occurs, we will notify the affected users, the
Data Protection Board of India and CERT-In as the law requires.
12. Your choices and rights
12.1 In-app controls
| You can |
Where |
| Edit or delete your profile, or remove your profile picture |
Profile settings |
| Make your profile private |
Privacy settings |
| Unfollow, block, or mute notifications from a wallet you follow |
The wallet's page |
| Choose which notifications you receive, or turn push notifications off |
Notification settings, or your device's settings |
| Remove watchlist tokens and alerts |
Watchlist and Alerts |
| Allow or stop analytics and crash reports |
Privacy settings |
| Delete your account data |
Settings > Delete account data |
Deleting your account data permanently removes what we hold for that
wallet address:
- your profile and profile picture;
- your chat messages and the reactions to them;
- your reactions and follows;
- your blocks, and the reports you filed;
- your invite records;
- your watchlist, alerts, notifications and push tokens;
- your settings, badges, sessions and sign-in record;
- your FireSat Pro badge. This cannot be undone or refunded.
What deleting does not remove:
- data on the public blockchain;
- FireSat Pro payment records, which we must keep by law;
- records of transactions you sent;
- token information you submitted that we have approved;
- reports others filed about you;
- other people's follows of your address.
Backups containing the deleted data are overwritten within 7 days. Your
wallet itself, on your device, is not affected.
12.2 Your rights under Indian law
Under the DPDP Act, you have the right to:
- get a summary of the personal data we process about you, how we process it,
and who we have shared it with;
- have inaccurate or incomplete data corrected, completed or updated;
- have your data erased when it is no longer needed, unless the law requires
us to keep it;
- withdraw your consent;
- have your grievances addressed (see section 16);
- nominate someone to exercise your rights if you die or become unable to.
12.3 If you are in the EEA or the UK
You also have the right to:
- access your data and receive a copy in a portable format;
- correct or erase it;
- restrict or object to processing;
- withdraw consent at any time;
- complain to your local data protection authority.
12.4 If you are in the United States
Depending on your state, you may have similar rights to know about, access,
correct and delete your personal information. We do not sell personal
information, and we do not share it for cross-context behavioural advertising.
We will not treat you differently for using your rights.
12.5 How to exercise your rights
Email contact@ciphervybe.com.
Because we do not know your name or email, we verify requests through the
wallet. We may ask you to sign a message with the wallet the request is
about. This proves you control it. We will never ask for your recovery phrase.
We reply within 30 days, or sooner if the law requires.
13. Children
The Services are only for people aged 18 or over. We do not knowingly
collect personal data from anyone under 18. If you believe a child has used
the Services, contact us. We will delete their data.
14. Cookies and browser storage
Our websites do not use advertising or analytics cookies. firesat.io and
bsv20.com set no tracking cookies.
The FireSat web app stores your wallet and settings in your browser's storage
on your computer. This is needed for it to work, and the data is not sent to
us. The FireSat app likewise keeps your recent searches on your
phone only, to show them under the search bar; they are never sent to us,
and Clear removes them. Our hosting providers may set technical cookies needed to deliver the
sites securely.
15. Third-party sites and services
The Services link to sites and services we do not control, such as:
- token websites and social accounts;
- searches for a token on social networks (X and Twetch), which send the
token's ticker to that network when you tap them;
- posting a Shill card about a token: the card is made on your phone, and
the words you wrote (with your @name, and your invite code in the
token's link, only if you chose to include them) go to the app or network
you pick when you tap Shill it;
- posting a P&L card about one of your positions: the card is made on your
phone and shows the result, prices and (unless you turn them off) the
amounts, with your @name and your invite (a code to scan, and in the
token's link) only if you chose them; it goes to the app or network you
pick when you tap Share P&L, and nothing is sent to us;
- blockchain explorers;
- app stores.
Their own privacy policies apply when you use them.
CipherVybe (OPC) Private Limited
- Registered office: H.No. 224, F/No. 3B, Rajgarh, Bylane 10, Silpukhuri, Guwahati, Kamrup, Assam 781003, India
- Email: contact@ciphervybe.com
Send questions, requests and grievances about your personal data to
contact@ciphervybe.com. This includes grievances under the Information
Technology Act, 2000 and its rules, and under the DPDP Act.
How complaints are handled:
- We acknowledge complaints within 24 hours.
- We resolve them within 15 days of receipt.
If you are not satisfied with our response, you may complain to the Data
Protection Board of India. If you are in the EEA or the UK, you may complain
to your local data protection authority.
17. Changes to this policy
We may update this policy as the Services or the law change. We will post the
new version with a new effective date.
If a change materially affects how we use your personal data, we will tell
you in the app or on our websites before it takes effect. Where the law
requires, we will ask for your consent again.
18. Language
This policy may be translated. If a translation differs from the English
version, the English version applies.